Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
8,460 exploits
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack10 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack09 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack09 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack08 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack08 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack08 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack08 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack08 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack08 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack07 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2012-315328 Jan 2014
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
60RISK
open
VulnCheck XDB
local
CVE-2013-6282HIGHunder attack21 Dec 2013
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not
98RISK
open
VulnCheck XDB
client-side
CVE-2013-3893HIGHunder attack15 Oct 2013
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 throug
100RISK
open
VulnCheck XDB
local
CVE-2013-259503 Oct 2013
The device-initialization functionality in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm
23RISK
open
VulnCheck XDB
initial-access
CVE-2022-22954CRITICALunder attackransomware01 Oct 2013
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2013-130009 Sep 2013
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, W
43RISK
open
VulnCheck XDB
local
CVE-2013-2596HIGHunder attack16 Jul 2013
Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain
71RISK
open
VulnCheck XDB
initial-access
CVE-2013-2597HIGHunder attack11 Jun 2013
Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6
71RISK
open
VulnCheck XDB
local
CVE-2013-2094HIGHunder attack05 Jun 2013
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RISK
open
VulnCheck XDB
local
CVE-2013-2094HIGHunder attack20 May 2013
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2013-2729HIGHunder attack15 May 2013
Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attack
83RISK
open
VulnCheck XDB
denial-of-service
CVE-2013-015611 Jan 2013
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RISK
open
VulnCheck XDB
local
CVE-2012-005629 Dec 2012
The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when
28RISK
open
VulnCheck XDB
local
CVE-2021-1732HIGHunder attackransomware01 Jan 0001
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2019-0211HIGHunder attack01 Jan 0001
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privilege
83RISK
open
VulnCheck XDB
client-side
CVE-2018-8174HIGHunder attackransomware01 Jan 0001
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISK
open
VulnCheck XDB
initial-access
CVE-2022-20699CRITICALunder attack01 Jan 0001
Cisco Small Business RV Series Routers Vulnerabilities
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-11580CRITICALunder attackransomware01 Jan 0001
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attac
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware01 Jan 0001
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
client-side
CVE-2018-0802HIGHunder attack01 Jan 0001
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISK
open
previouspage 282 / 282

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.